A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.
{
"severity": "High",
"cpes": [
"cpe:2.3:a:kubernetes:ingress-nginx:*:*:*:*:*:*:*:*",
"cpe:2.3:a:kubernetes:ingress-nginx:1.0.0:*:*:*:*:*:*:*"
]
}